canonical/cloud-init

World writable /usr/lib/cloud-init/clouddir should not be left behind

開放

#4,189 建立於 2023年6月15日

 (5 則留言) (1 個反應) (0 位負責人)Python (1,108 個分叉)auto 404
buggood first issue

倉庫指標

星標
 (3,772 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

Bug report

Work was done last year to ensure that when /tmp and /var/tmp are hardend with noexec, cloud-init will use an alternative path under /usr/lib/cloud-init

However, /usr/lib/cloud-init/clouddir is created as world writable and left behind after cloud-init has exited.

Steps to reproduce the problem

Run cloud-init with a /tmp and /var/tmp that are mounted with noexec

If possible, /usr/lib/cloud-init/clouddir should be created as non-world read/writable. But if that's not possible, at the least it should be removed when cloud-init exits.

貢獻者指南